Sceawere
Vulnerability Detail
CVE-2026-65656UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Office Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- Attack Type
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-11T17:18:53.703Z",
"pubdate": "2026-08-11T17:18:53.703Z",
"executiveSummary": "A command injection vulnerability has been identified in Microsoft Office, classified as CWE-77 (Improper Neutralization of Special Elements used in a Command).\nThis security flaw allows an unauthorized local attacker to execute arbitrary code within the context of the current user.\nThe vulnerability affects Microsoft Office and poses significant risk implications regarding local system integrity and confidentiality.\nExploitation requires the execution of locally crafted input or files designed to leverage improper command neutralization within the vulnerable application components.\nSuccessful exploitation grants the attacker the ability to execute system-level or user-level commands, potentially leading to full system compromise depending on the privileges of the affected user session.",
"technicalDetails": "The root cause of the vulnerability stems from improper neutralization of special characters and elements used in system commands processed by Microsoft Office components.\nThe vulnerable component fails to adequately sanitize or validate user-supplied input or structured data before passing it to underlying operating system command interpreters or shell execution functions.\nThe attack vector involves local exploitation where an unauthorized threat actor induces the application to process maliciously crafted input or files containing injected command sequences.\nDuring the attack flow, the affected Microsoft Office parser or handler encounters special metacharacters that are misinterpreted as command delimiters rather than literal data.\nThis misinterpretation allows the injected payload to break out of the intended data context and execute arbitrary operating system commands with the privileges of the user running the Microsoft Office process.\nAuthentication and network exposure requirements are minimal or non-applicable for the initial local vector, as the flaw relies on local file processing or user interaction with untrusted content.\nPrivilege requirements are constrained by the access level of the targeted user running the vulnerable application instance.\nPost-exploitation impact includes arbitrary code execution, unauthorized data access, potential lateral movement, and persistence establishment within the local environment."
}